Why Versa Sovereign SASE? The Critical Challenges of Security Compliance and Control
As organizations navigate evolving security, compliance, and operational challenges, the need for a more flexible, sovereign approach to SASE has never been greater. In this session, Versa CEO Kelly Ahuja will explore the business drivers behind the need for Sovereign SASE, including data sovereignty requirements across different regions and industries; operational control and business continuity challenges when relying on multi-tenant, cloud-native SASE models; and security limitations of standard cloud-delivered SASE.
Presented by Kelly Ahuja, CEO. Recorded live at Networking Field Day 37 in San Francisco, CA on March 19, 2025. Watch the entire presentation at https://techfieldday.com/appearance/versa-presents-at-networking-field-day-37/ or visit https://techfieldday.com/event/nfd37/ or https://www.Versa-Networks.com/ for more information.
Transcript
Hey everyone. Um, thank you for the opportunity for being here. I'm Kelly Ahuja, I'm the president, CEO for Versa Networks.
And, uh, happy to come and talk to you about a few things. One, um, before we get too much into Sovereign Sass e what I thought we'd do is tell you who we are, what we do, and what problem we're really trying to solve. Um, not just with Sass e 'cause I'm sure you know what all that is, but really about what Sovereign Sass.
So we're gonna talk about that. Uh, Annu Dia is gonna join me, and Adrian's also gonna join me as well. In completing the picture, we're gonna talk about, uh, a, the initial part, Annu is gonna talk about the offer itself, what, what we do, why it's different, and how it's better.
Uh, and then Adrian's gonna do a lot more tech, deep dive, and even a show and tell. Okay, great. So with that, let's get started.
So first of all, um, you know, what are we doing with, uh, with Adva? So, um, here's kind of what the normal, um, normalized approach is today for any enterprise, uh, or any business, let's call it that. Um, SE has become kind of the defacto framework or an architecture for connecting any user, any device, any location and any workload if you want to, to any, um, uh, to any workload itself or application, wherever it may be.
Whether it's in SAS or internet connected or private data center, or private cloud, or even in, uh, public cloud. Now, there's a lot of acronyms, uh, that make up SSE, everything from SD-WAN to RBI to ZTNA to DLP, to all those pieces put together. Each one is important.
And the challenge has been that in the industry, that up until now, every one of those has been a typical product that you can buy from a particular vendor and deploy it, and then you're left to integrate all those together. So that's been the way of the, the past and the future. And you'll see more of that coming up as we go through this.
So what, who is versa and what's our mission? Well, versa started, I was founded in 2012. Uh, we've evolved, um, our, our products and portfolios since that time.
Our mission is really to secure anywhere, anytime, access to anything with the last phrase that's missing here, which is tailored to meet the customer's needs. And today that sovereign ss e we're gonna talk about is really tailored to meet the customer's needs. So you'll see more about that.
So what do we do at Versa? Well, we protect everything everywhere. Our security stack is, um, uh, is available at anywhere where our software stack runs.
So we secure any edge. And typically that edge is a network edge or security edge. It doesn't really matter to us.
They're both the same. So we secure every edge, protect every edge. Uh, we accelerate detection and threat, uh, threat response.
Uh, we connect anyone to anything anywhere and ensure that there's a good user experience because we know exactly what the conditions of the network are at any given time. And like ways or Google Maps, we connect you through the best path to where you're trying to go automatically. And lastly, we simplify and streamline operations.
This is the most important thing for most enterprises today. They're mired in complexity in their architecture and they're trying to simplify things because they wanna move fast. They want to meet the business needs, um, and also save money.
So simplification, automation, uh, operational efficiency is a key area for every business out there that they're looking to go solve. So that's kind what we do as well. So just a quick introduction today.
Versa, we have lots of customers. We're working with lots of partners and, um, uh, we're in deployed in multiple countries. So, uh, very simply put what we do well, we're a disruptive innovator.
We pioneered the convergence of network insecurity as I'm about to show you. Um, and that's been there since day one of the company's founding since 2012. Um, we're a market leader today, uh, not just in SS e but in multiple market categories.
But essentially what we do is we actually have been using zero trust principles at any edge. And today that edge can be a cloud edge, which is what most SSE or security services edge players do. But we can also be on the WAN edge because if you're an SE WAN player, you do that.
But we've also extended that to the LAN edge as I'm about to show you. Okay. So we'll go through that too.
And lastly, we've got global, global reach. Um, we've got a very highly efficient go-to-market model. We've been, um, uh, the Kirkland in many service providers, Costco, silently over many years.
So we're the house brand that service providers will use to go sell you their services. So it doesn't show up as our brand, but it's our stuff that's actually getting deployed. And there are millions of users and thousands of enterprises that are actually doing it, doing, using versa without knowing it.
And lastly, we're we have broad adoption. Our adoption is across large enterprises across every vertical, whether it's financial, uh, banking, uh, news agencies, retailers, uh, uh, energy companies, uh, oil and gas, uh, defense, public sector, you name it. We're deployed in many places and we're deployed across the world.
And not only that, we're also deployed in service providers, as I said. So, uh, with that in mind, let's kind of tell you a little bit what we've done in the history of versa up, um, the traditional approach. You know, I've been around networking industry for a while and now security as well.
This was the old way of building out your network. You decided which part of the network you were trying to build, whether it was a wide area network or your land or campus or inside the branch. If it was a cloud or a multi-cloud that Tom was talking about earlier or even inside the data center.
Then you went up and said, okay, what, what, what do I need in terms of building blocks and what are my options? And you went ahead and chose the building blocks and you bought them and you stitched them. Now you have the tough point, which is stitch 'em together.
Then comes the harder part, which is lifecycle management. You gotta do the upgrades, you gotta make sure everything's working fine before you deploy a software release. And you kind of continue that cycle over.
And it was like, um, uh, one customer put it to us, which is they were living on the X every day. They were running harder and harder on that treadmill. They didn't have a chance to get off that treadmill or even think about how they're gonna get off that treadmill.
'cause before they turned around, there was a new software release or a patch of some product or the other, and they were doing that. So that complexity across different places in the network multiplied even more so because in the lan, what you did was not the same as what in the WAN or in the cloud. So different solutions everywhere.
Now you gotta stitch 'em together. Well, v's approach was quite different. What we did starting in 2012 is we said, why do you need all these boxes?
Why not take all the software feature set software features that you have in this area and build them into a single software stack? A unified operating system that isn't like a, an old multi-protocol router, but it's a multi-service or multi-layer infrastructure that does everything from layer to layer seven. And when you have that, what if you put that a on an appliance?
Could it be a WAN appliance, like a next 86 based appliance or a LAN switch or a cloud edge, um, or all of them, um, or even put it in the cloud, uh, in a virtual environment, a virtual instance, and then have someone connect to it, whether it's a user or device, um, or a location or have those cloud instances connect to each other. So all possible, and it's simple software stack that kind of does us all these functions all in one cloud native. Just give it the amount of CPU cores you need and it'll scale out and scale in whichever way you need it to.
So very efficient, very um, um, very well built and deployed with a lot of maturity with all the feature sets that you would typically need, um, in any location across any network with security being built in, into the same stack. And it's not just a firewall. It's a best firewall in the industry according to some people that have done, done some testing.
But it's also got C-A-S-B-D-L-P-Z-T-N-A swig, you name it, it's all there. Can I ask you a Question, Kelly? Please, Scott, go ahead.
Um, So that's a lot of competing functionality in a single platform. What have you done from an internal architecture perspective to make sure you keep the hot stuff hot and the cold stuff cold, like the right processes, get the right resources? Absolutely.
And that's where a lot of the architectural, the software foundation of the architecture, we worked with Intel many years ago using, you know, D-P-D-K-S-R-I-O-V and all those other things, QAT, um, leveraging all those capabilities. But then the fundamental architecture of inside the software leverages a very efficient architecture of how packets come in, how we take, take those packets apart and how we apply those packets to different services, almost like an ASIC does in the hardware world. If you remember correctly from, from what when we used to work in the past, um, we've done done something similar.
Okay? It's a pipeline based engine, very efficiently organized and service chained together. And it's not different virtual functions that are being service chain.
It's the same software stack and it's almost like a micro services or DLLs that are kind of coming together and stitching those services. Adrian is gonna go into that a little bit when he goes through more detail. Okay, All right, so what have we done?
Well, we took that software stack and we said, you know what? It'd be really cool to have a single data lake with this. 'cause now you've got all the software running, everything, whether it's security, networking, you take all that telemetry, put it into a single data lake, then you have a single unified policy engine that basically allows you to say, Hey, it's Kelly.
He's at this location. Or if he's at the office or he is not at the office, what is his policy? What is his security policy and what's his access policy?
And lastly, then you have a single consult to monitor it all. Now you can take that stack and the whole platform and build it into a platform because at the bottom now you have, um, um, all, all the other other pieces that you need built in with ai, uh, with zero trust framework, with also, um, scalable, um, multiplane architecture. What do we mean by multiplane?
While there's data plane control, plane and management plane. And the way that we've designed the software and the architecture and the platform is that each is isolated. So you can scale one in any dimension and not have it affect the other.
So control plane completely isolated from, um, data plane and management plane. So very efficient architecture, it integrates with anything that's out there. Typically we have outta the box integration with many of the endpoint providers or, uh, the SIM providers or other SSE players or other SD WAN players or other firewall players.
So pretty much everything is kind of there outta the box. If it isn't, we do a very quick, uh, turnaround. If a customer says, Hey, I need you to work with this, we'll take that and we'll actually put that together very quickly.
Um, also threat intelligence. We have our own threat intelligence feed. Our, our threat research team does a lot of work on that.
But if you have your own and you really want to add that to the mix, yeah, you can add that too. And we'll take that, that as well and incorporate it very differentiated for many large enterprises and carriers. So now you've taken all of that pieces and you've actually got, uh, solutions built coming out of it.
So what are the solutions that we came up with? Well, uh, let me kind of use the next slide to come up, come up with that. But, um, when you package it all together, that's what we call universal sass.
E SASS e up until now is only address two things, which is one locations with SD WAN or remote users with um, ZTNA, uh, and coming into a cloud, what we felt was that why should security be only in the cloud? Why? Because security in the cloud is only, for many cases, only addresses client to server.
It does not address server to client. So there are many things like that that you have to worry about and and wonder. Uh, so that's why we have on-prem security, we have cloud security, we have secure SD WAN and also secure SD lan where we can actually run our software on some certified switches that we have.
And you can actually get the same functionality in line security firewall, separation, isolation, um, and also SSE capability all the way down into a switch. So as a company, what we did is we actually first introduced this capability into two things. One is sd-wan.
The second thing is SSE. Over time we've evolved that. Now if you'll notice, even our SD-WAN has options.
The options are you can do zero trust, network access on premises, you can actually do inline Cs, B and DLP. Our SSE is served from the cloud and it's been served from our cloud because we've actually built a cloud with a fabric. If you look down below, there's a high traffic engineered fabric, which actually connects all our nodes and gateways.
Combine that together, you get a simple solution, which is unified ss e you get both SD-WAN and SSE for either locations or devices or users. What we did then is we said, Hey, our security's pretty good, so why don't we start selling our security? Because there's a need for a lot of security things that are out there.
So we actually built an IOT security into the stack. We've got I-P-S-I-D-S ATPs available and even a geni firewall. And lastly, I'll be taking that full stack down to the lan and you can actually build your campus, um, with EVPN based overlays as you wouldn't do in the data center.
But with security built in secure overlays, running across any fabric that you may have already existing from any other vendor. And of course, AIOps, no, no conversation can start or run without AIOps. And yes, we have all the things that you would need to, everything from dem, uh, to UEBA and also, um, copilots, et cetera.
Okay, but enough of that. Let's talk about why Sovereign SAS e. So we've been happily selling this software stack from our cloud as a service, uh, versus secure private access versus secure internet access versus secure access fabric, which is a combination of SSC and SD wan.
But customers started coming to us and saying, Hey, um, I can't, I can't go to cloud. I have to do this on my own, in my own area. This is a public company, a CIO, a very large bank that basically publicly stated this comment.
Another set of customers came in and said, you know what? We're international. We're worried about the bad guys around the world.
But it's not just the bad guys. We're worried about, we're also worried about the details of what's captured in the cloud Act, where any user information that we may have as a US company, even if the user and the, and the provider is somewhere outside the US has to be provided back to the government. Lastly, uh, concerns and risk around risk of, uh, cloud and SaaS.
Um, there's been incidents out there which have actually hurt a lot of businesses and they're looking for resiliency, business continuity, and they're wondering if there's a better approach to kind of go do this. So this has been going on for quite some time. Customers have been asking for many things.
This started in initially in one vertical, and now it's spread to other verticals where we thought it was the right time to actually do what we've been, take what we've been doing for many years and really bring it to market in a broader way. And that's why we introduced the concept of sovereign sas.